Information Security Analyst
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Network Security, Security Management & Operations, Information Security & Data Protection
Job Description About the Role
We are seeking an experienced Information Security Analyst to support security operations, incident response, vulnerability management, digital forensics, and security automation within a complex enterprise environment. This is a hands-on technical role operating as a senior practitioner within a Security Operations Center (SOC). The Information Security Analyst will investigate security alerts and incidents, improve detection capabilities, support vulnerability remediation, administer and enhance security technologies, and develop automation using Python and Power Shell.
The position requires practical experience with SIEM and endpoint security platforms, Microsoft security technologies, firewall administration, identity and access technologies, Windows and Linux environments, and AI-assisted security tooling. The analyst will also provide technical guidance and mentorship to junior SOC team members.
- Monitor network, endpoint, system, application, and identity telemetry for potential security threats.
- Investigate IDS/IPS and EDR alerts, security logs, system events, and network traffic to identify suspicious or malicious activity.
- Perform second-level analysis of escalated alerts, determine severity and relevance, distinguish legitimate threats from false positives, and document findings.
- Use SIEM and log-analysis platforms such as Splunk, Elastic/Open Search, Kibana, and Microsoft Sentinel to investigate and correlate security events.
- Operate, tune, and recommend improvements to SIEM, EDR, endpoint security, and other SOC technologies.
- Support Microsoft Defender and related Microsoft security technologies for alert investigation, containment, and response.
- Develop threat-hunting and detection strategies based on emerging threats, observed activity, and established attack frameworks.
- Identify and integrate additional security data sources to improve monitoring and detection coverage.
- Develop Python 3 and Power Shell scripts to automate detection, enrichment, investigation, response, and security data analysis.
- Support firewall administration, including security policy enforcement and ruleset maintenance.
- Incorporate AI-assisted security capabilities into investigation, detection, analysis, automation, and response workflows.
- Serve as a technical first responder for suspected and confirmed cybersecurity incidents.
- Perform endpoint, identity, network, log, and system-level analysis to determine incident scope, impact, and potential root cause.
- Support incident containment, eradication, evidence preservation, and recovery activities.
- Conduct first-responder-level digital forensic analysis and breach assessment.
- Prepare clear incident documentation and communicate findings to technical leadership and relevant stakeholders.
- Configure and review vulnerability scans and analyze identified security weaknesses.
- Prioritize vulnerabilities based on severity, exploitability, exposure, and business impact.
- Coordinate remediation activities with infrastructure, application, networking, and system owners.
- Validate remediation activities and monitor patching effectiveness for critical findings.
- Mentor junior SOC analysts in alert investigation, log analysis, incident documentation, and escalation practices.
- Assist with the onboarding, training, and day-to-day technical oversight of junior security team members.
- Develop and maintain SOC runbooks, operating procedures, investigation workflows, and escalation guidelines.
- Bachelors degree in Cybersecurity, Information Security, Computer Science, Computer Engineering, Information Management, or a related technical discipline.
- 5+ years of professional Information Technology experience.
- 2+ years of professional Information Security or Cybersecurity experience.
- 2+ years of hands-on SOC operations experience involving IDS/EDR alert triage, log analysis, and network traffic interpretation.
- 2+ years of experience with SIEM or log-analysis technologies such as Splunk, Kibana, Elastic/Open Search, or Microsoft Sentinel.
- 2+ years of experience with Microsoft Defender for Endpoint, including alert triage, investigation, and response.
- 2+ years of Python 3 scripting experience supporting security automation, analysis, or SOC workflows.
- 2+ years of experience with firewall administration and network security fundamentals.
- 1+ years of experience with Windows and Active Directory administration and security.
- 1+ years of experience analyzing endpoint and Windows security logs.
- 1+ years of experience with Power Shell scripting and Group Policy.
- 1+ years of Linux system administration experience.
- 1+ years of first-responder-level digital forensic experience.
- 1+ years of experience using AI-assisted security technologies, including AI-enabled SIEM, investigation, automation, or productivity capabilities.
- Experience working in a production SOC or comparable security operations environment investigating active security alerts and incidents is…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).